CVE-2025-25800

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 26, 2025
CWE ID 22

Summary

CVE-2025-25800 is a newly discovered vulnerability affecting SeaCMS version 13.3. The issue resides in the file_get_contents function present in admin_safe_file.php. An attacker can exploit this arbitrary file read vulnerability to read sensitive information stored on the affected system, potentially leading to unauthorized access and data breaches. The vulnerability poses a significant risk to websites using SeaCMS 13.3, and administrators are advised to update their installations as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share